
CVE-2026-7669-PoC
PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

A dead simple tool to sign files and verify digital signatures.

A Python library to parse, validate and create SPDX documents.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

CVE-2026-43813: CloudAttestation enforceEnvironment bypass